Senior macOS Engineer – Workforce AI Security
Posted 11hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior macOS Engineer owning native endpoint security agents for Check Point’s enterprise AI platform. Building TLS interception, proxy controls, and data-loss protections across managed Macs.
Responsibilities:
- Own the macOS agent end-to-end
- Architect and maintain privileged system services, inter-process communication, and robust self-updating mechanisms across non-administrated endpoints
- Implement TLS interception and certificate trust chains on macOS
- Resolve system proxy configuration conflicts alongside endpoint security tools, VPNs, and cloud proxies
- Build native interception capabilities for AI developer tools to monitor and apply data-loss policies
- Enforce fail-open architecture so local failures do not degrade network connectivity or access to corporate assets
- Analyze customer logs and clean-state Mac reproductions to identify root causes and ship permanent fixes
- Own product fixes for conflicts with other endpoint security products
- Serve as principal technical authority for macOS engineering decisions across R&D
Requirements:
- 5+ years of systems-level software development
- 3+ years delivering production macOS software using Swift and Objective-C
- Deep expertise in macOS platform internals, including launchd, XPC, code signing, notarization, packaging, privileged operations, and debugging complex runtime behavior
- Solid grounding in networking fundamentals, including system proxies, TLS, certificate trust, and application-to-internet connections
- Hands-on proficiency with modern AI development tools such as Claude Code or Cursor
- Critical, verification-first approach to AI-generated code
- Clear technical communication skills
- Experience resolving critical technical issues alongside field engineers and enterprise IT teams
- A CS degree or equivalent practical engineering background
Benefits:
- Building a native macOS platform rather than maintaining a ported Windows client
- Full technical ownership over privileged services, trust chains, proxy configuration, and network components
- Engineering culture enforcing strict "fail open" reliability
- Root-cause product fixes rather than customer-side exclusions or temporary workarounds



















